CVE-2022-41136: WordPress Shortcodes Ultimate plugin <= 5.12.0 - CSRF vulnerability leading to Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Shortcodes Ultimateto a version that resolves this vulnerability.Fixed in 5.12.1
Event History
Frequently Asked Questions
What is CVE-2022-41136?
CVE-2022-41136 is a Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in the Shortcodes Ultimate plugin <= 5.12.0 on WordPress.
How severe is CVE-2022-41136?
CVE-2022-41136 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2022-41136?
The Shortcodes Ultimate plugin versions up to and including 5.12.0 on WordPress are affected by CVE-2022-41136.
How can I fix CVE-2022-41136?
To fix CVE-2022-41136, update the Shortcodes Ultimate plugin to a version higher than 5.12.0.
What are the references for CVE-2022-41136?
You can refer to the following links for more information on CVE-2022-41136: [Patchstack](https://patchstack.com/database/vulnerability/shortcodes-ultimate/wordpress-shortcodes-ultimate-plugin-5-12-0-csrf-vulnerability-leading-to-stored-xss?_s_id=cve) and [WordPress Plugin Directory](https://wordpress.org/plugins/shortcodes-ultimate/#developers).